PluginProbe
Timetics – Appointment Booking Calendar & Scheduling / 1.0.64
Timetics – Appointment Booking Calendar & Scheduling v1.0.64
1.0.64 1.0.62 1.0.63 1.0.61 1.0.60 1.0.59 1.0.58 1.0.57 1.0.56 trunk 1.0.0 1.0.1 1.0.10 1.0.11 1.0.12 1.0.13 1.0.14 1.0.15 1.0.16 1.0.17 1.0.18 1.0.19 1.0.2 1.0.20 1.0.21 All 65 releases
← All changes | core/staffs/api-staff.php +49 -18 1.0.17 → 1.0.64 View file →
@@ -5,8 +5,10 @@
5 5 * @package Timetics
6 6 */
7 7 namespace Timetics\Core\Staffs;
8 8
9 +defined( 'ABSPATH' ) || exit;
10 +
9 11 use Timetics\Base\Api;
10 12 use Timetics\Core\Integrations\Google\Client;
11 13 use Timetics\Core\Staffs\Staff;
12 14 use Timetics\Utils\Singleton;
@@ -45,11 +47,9 @@
45 47 $this->namespace, $this->rest_base, [
46 48 [
47 49 'methods' => \WP_REST_Server::READABLE,
48 50 'callback' => [$this, 'get_items'],
49 - 'permission_callback' => function () {
50 - return true;
51 - },
51 + 'permission_callback' => [$this, 'get_staffs_permission_callback'],
52 52 ],
53 53 [
54 54 'methods' => \WP_REST_Server::CREATABLE,
55 55 'callback' => [$this, 'create_item'],
@@ -60,9 +60,9 @@
60 60 [
61 61 'methods' => \WP_REST_Server::DELETABLE,
62 62 'callback' => [$this, 'bulk_delete'],
63 63 'permission_callback' => function () {
64 - return current_user_can( 'manage_timetics' );
64 + return current_user_can( 'manage_options' );
65 65 },
66 66 ],
67 67 ]
68 68 );
@@ -83,10 +83,10 @@
83 83 ],
84 84 [
85 85 'methods' => \WP_REST_Server::EDITABLE,
86 86 'callback' => [$this, 'update_item'],
87 - 'permission_callback' => function () {
88 - return current_user_can( 'manage_timetics' );
87 + 'permission_callback' => function ( $request ) {
88 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
89 89 },
90 90 ],
91 91 [
92 92 'methods' => \WP_REST_Server::DELETABLE,
@@ -91,9 +91,9 @@
91 91 [
92 92 'methods' => \WP_REST_Server::DELETABLE,
93 93 'callback' => [$this, 'delete_item'],
94 94 'permission_callback' => function () {
95 - return current_user_can( 'manage_timetics' );
95 + return current_user_can( 'manage_options' );
96 96 },
97 97 ],
98 98 [
99 99 'methods' => \WP_REST_Server::READABLE,
@@ -110,9 +110,9 @@
110 110 [
111 111 'methods' => \WP_REST_Server::READABLE,
112 112 'callback' => [$this, 're_invite_staff'],
113 113 'permission_callback' => function () {
114 - return true;
114 + return current_user_can( 'manage_options' );
115 115 },
116 116 ],
117 117 ]
118 118 );
@@ -122,9 +122,9 @@
122 122 [
123 123 'methods' => \WP_REST_Server::READABLE,
124 124 'callback' => [$this, 'search_items'],
125 125 'permission_callback' => function () {
126 - return current_user_can( 'edit_posts' );
126 + return current_user_can( 'manage_timetics' );
127 127 },
128 128 ],
129 129 ]
130 130 );
@@ -133,10 +133,10 @@
133 133 $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations', [
134 134 [
135 135 'methods' => \WP_REST_Server::READABLE,
136 136 'callback' => [$this, 'get_integrations'],
137 - 'permission_callback' => function () {
138 - return current_user_can( 'edit_posts' );
137 + 'permission_callback' => function ( $request ) {
138 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
139 139 },
140 140 ],
141 141 ]
142 142 );
@@ -145,10 +145,10 @@
145 145 $this->namespace, $this->rest_base . '/(?P<staff_id>[\d]+)/integrations/auth-revoke', [
146 146 [
147 147 'methods' => \WP_REST_Server::READABLE,
148 148 'callback' => [$this, 'auth_revoke'],
149 - 'permission_callback' => function () {
150 - return current_user_can( 'edit_posts' );
149 + 'permission_callback' => function ( $request ) {
150 + return current_user_can( 'manage_options' ) || (int) $request['staff_id'] === get_current_user_id();
151 151 },
152 152 ],
153 153 ]
154 154 );
@@ -498,9 +498,8 @@
498 498
499 499 return new WP_HTTP_Response( $data, 404 );
500 500 }
501 501
502 - $token = timetics_get_google_access_token( $staff_id );
503 502 $client = new Client();
504 503
505 504 $revoked = false;
506 505
@@ -505,18 +504,31 @@
505 504 $revoked = false;
506 505
507 506 switch( $integration ) {
508 507 case 'google-auth':
509 - $revoked = $client->revoke( $token );
510 - if ( $revoked ) {
511 - update_user_meta( $staff_id, 'timetics_google_auth', '' );
508 + $refresh_token = timetics_get_google_refresh_token( $staff_id );
509 + if ( ! empty( $refresh_token ) ) {
510 + $client->revoke( $refresh_token );
512 511 }
513 512
513 + // Always clear ALL local Google credentials so the account can be reconnected cleanly.
514 + delete_user_meta( $staff_id, 'timetics_google_auth' );
515 + delete_user_meta( $staff_id, 'timetics_google_refresh_token' );
516 + delete_user_meta( $staff_id, 'timetics_google_auth_code' );
517 + delete_user_meta( $staff_id, 'timetics_google_auth_error' );
518 +
519 + $revoked = true;
520 +
514 521 break;
515 522 case 'zoom-auth':
516 523 $revoked = true;
517 524 update_user_meta( $staff_id, 'timetics_zoom_token', '' );
518 525 break;
526 +
527 + case 'outlook-auth':
528 + $revoked = true;
529 + update_user_meta( $staff_id, 'timetics_outlook_token', '');
530 + break;
519 531 }
520 532
521 533 if ( ! $revoked ) {
522 534 $data = [
@@ -658,9 +670,28 @@
658 670 * @return array staff data
659 671 */
660 672 public function prepare_item( $staff ) {
661 673 $staff = new Staff( $staff );
674 + $data = $staff->get_data();
662 675
663 - return $staff->get_data();
676 + if ( ! current_user_can( 'manage_timetics' ) ) {
677 + unset( $data['email'], $data['phone'], $data['user_name'] );
678 + }
679 +
680 + return $data;
664 681 }
665 682
683 + /**
684 + * Get items permission callback
685 + *
686 + * @param WP_Rest_Request $request
687 + *
688 + * @return boolean true if user has permission, false otherwise
689 + */
690 + public function get_staffs_permission_callback($request){
691 + $nonce = $request->get_header('X-WP-Nonce');
692 + if (wp_verify_nonce($nonce, 'wp_rest') && ( current_user_can( 'manage_timetics' ) || current_user_can( 'manage_options' ) ) ) {
693 + return true;
694 + }
695 + return false;
696 + }
666 697 }